Google Deploys Verifiable Private Federated Learning for Gboard
Google Research has rolled out a federated‑learning system that uses trusted execution environments and public transparency logs, promising externally verifiable privacy for Gboard’s next‑word prediction in English and Japanese.

Google Research has introduced a fresh federated‑learning architecture that relocates critical components of the training workflow into attested server enclaves built on trusted execution environments, or TEEs. This redesign aims to make the differential‑privacy guarantees of the system externally verifiable, moving beyond the previously opaque privacy assurances that characterized earlier federated configurations.
Architecture Overview
In the new design, each client device encrypts its training examples and appends an access policy that specifies precisely which server‑side TEE program is permitted to decrypt the data and which anonymised outputs may be released. The policy is cryptographically bound to the encrypted payload, guaranteeing that only authorised workloads can ever access the raw information.
A dedicated key‑management cluster, also operating inside TEEs, employs the RAFT consensus protocol to coordinate decryption keys. Keys are handed out solely to workloads that satisfy the published policy, thereby blocking rogue processes from obtaining the data even if they manage to compromise the enclave environment.
Public Auditing with Rekor
Every access policy generated by the system is written to the public Rekor transparency log. External auditors can query this log to identify exactly which server workloads have been authorised to process encrypted examples, creating an immutable audit trail that can be inspected without reliance on Google’s internal infrastructure.
- Policies published in Rekor for public inspection
- TEE‑hosted key‑management cluster using RAFT
- Reproducible binaries from the Confidential Federated Compute repo
- Only metrics and DP model weights leave the enclave
Impact on Gboard
Google reports that the English and Japanese next‑word prediction models powering Gboard are now trained using this verifiable private federated learning system. According to the company and the accompanying research paper, the new pipeline yields faster training cycles, higher prediction accuracy, and a reduced privacy budget compared with the legacy production system.
By shifting gradient computation and scheduling responsibilities to the server side, the architecture lessens the dependence on simultaneous device availability. This flexibility enables optimisation of privacy parameters across larger and more diverse user cohorts, thereby enhancing the overall utility of the differentially private model.
Only aggregated metrics and differentially private model weights ever exit the enclave environment. Raw encrypted examples remain inside authorised enclaves for a limited window before being automatically destroyed, which narrows the attack surface for potential data leakage.
Google also publishes the key‑management and data‑processing binaries as reproducibly buildable artifacts from the open‑source Confidential Federated Compute repository. This transparency allows independent parties to verify that the code executing inside the enclaves matches the published source.
Nevertheless, TEEs continue to face generation‑specific constraints and remain vulnerable to certain side‑channel attacks. While public verifiability of code and policies adds a layer of assurance, it does not eradicate all risks stemming from hardware flaws, implementation bugs, or broader data‑governance practices.
For organisations that depend on Gboard or comparable federated‑learning services, the upgrade means they can now reference a system where privacy guarantees are not merely asserted but can be audited through publicly accessible logs. This capability bolsters regulatory confidence, particularly in jurisdictions that require demonstrable compliance with stringent data‑protection standards.
Technical Foundations
The system’s reliance on TEEs ensures that code execution occurs in an isolated hardware enclave, shielding it from the host operating system. Combined with RAFT‑based key management, this creates a robust chain of trust from data ingestion to model update.
Future Directions
Google plans to extend the verifiable private federated learning framework to additional languages and to other on‑device services beyond Gboard. Ongoing research aims to mitigate side‑channel vectors and to integrate newer generations of TEEs as they become commercially available.
The initiative also invites the academic community to scrutinise the reproducible binaries and the public Rekor entries, fostering a collaborative ecosystem for privacy‑preserving machine learning.
In summary, the deployment marks a significant step toward making federated learning both private and externally auditable, setting a new benchmark for on‑device AI services.
This article was compiled from sources released by Google Research on 2 October 2026 and the corresponding arXiv pre‑print dated 25 September 2026, and reflects the state of the technology as of early October 2026, reported from Mountain View, California.
Sources
- Toward provably private learning from federated dataGoogle Research · October 2, 2026
- Toward provably private learning from federated dataarXiv · September 25, 2026



